Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

7 / 7 results
Active filter:tag: #sap✕ clear
SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited

SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.

SAP18 Aug · 13:07 UTC
SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch

SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.

CVE-2026-5823115 Aug · 06:38 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)

SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.

CVE-2026-5823112 Aug · 05:31 UTC
Fortinet FortiSandbox command injection flaw enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox command injection flaw enables remote code execution

Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.

CVE-2026-2508910 Jun · 13:10 UTC
SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloudcriticalbug_reportVulnerability
bug_reportVulnerability

SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud

SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.

SAP9 Jun · 17:36 UTC
SAP releases critical patches for multiple productscriticalbug_reportVulnerability
bug_reportVulnerability

SAP releases critical patches for multiple products

Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.

SAP9 Jun · 12:23 UTC